1.Who we are
zutpralik is a website-monitoring platform for agencies and their clients, operated by [[COMPANY_LEGAL_NAME]], registered at [[REGISTERED_ADDRESS]], company number [[COMPANY_NUMBER]], VAT number [[VAT_NUMBER]] (“zutpralik”, “we”, “us”).
For questions about this policy, about how we handle personal data, or to exercise any of the rights described in section 10, contact us at [[CONTACT_EMAIL]].
We have not appointed a Data Protection Officer. Where one is required, or where the relevant contact differs from the address above, it will be named here: [[CONTACT_EMAIL]].
2.Scope: when we are the controller and when we are a processor
zutpralik is multi-tenant. An agency (our customer) creates a workspace, and inside it records its own clients, their websites and their invoices. That split matters under the GDPR, because it decides who is answerable for what:
| Data | Controller | Our role |
|---|---|---|
| Your own account and workspace — the account you registered, your users, your subscription and the invoices we issue to you | zutpralik | Controller. This policy applies in full. |
| The data you enter about your clients — client company records, contact e-mail addresses, their sites, their monitoring results, incidents and the invoices you raise to them | You (the agency) | Processor. We process it only on your documented instructions, under our Data Processing Agreement. |
| Visitors to zutpralik.click — people reading our public website | zutpralik | Controller. We set no cookies and run no analytics — see Cookies. |
If you are the client of an agency that uses zutpralik and you want your data corrected or deleted, contact that agency first: they decide what happens to it. We will help them act on your request, and we will forward requests we receive directly.
3.What personal data we process
The list below is exhaustive as of the “last updated” date. It describes the data the platform actually stores, not a generic superset.
| Category | What it contains |
|---|---|
| Account data | Name, e-mail address, a bcrypt hash of the password (never the password itself), role, and creation/update timestamps. |
| Client records | Company name, contact e-mail address and company details such as an address — entered by the agency about its own clients. |
| Monitored sites | URLs and check configuration (for example a keyword to look for or a TCP port to test). |
| Monitoring results | HTTP status codes, response times, error text returned by the site, SSL certificate and domain expiry dates, and DNS records. |
| Incidents and activity events | When a site went down and recovered, and a feed of the changes made in the workspace. |
| Billing data | Invoices and the billing details entered by the agency (amounts, periods, payment status). |
| Notification channels | E-mail addresses, Telegram chat ids, webhook URLs, Slack and Discord incoming-webhook URLs and PagerDuty integration keys used to receive alerts, plus a delivery log recording what was sent and whether it succeeded. |
| Security records | An impersonation audit log for administrator “view as user” sessions, which stores the IP address and user-agent of the administrator; invitations (e-mail address, valid 7 days); and password-reset tokens, stored only as hashes and valid 60 minutes. |
Monitoring results describe machines, not people, but they can be linked to the agency and client who own the site, so we treat them as personal data throughout this policy.
4.Why we process it, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and running your account; authenticating you | Account data, invitations, password-reset tokens | Contract — Art. 6(1)(b) |
| Running checks against the sites you add and recording the results | Sites, monitoring results, incidents | Contract — Art. 6(1)(b) |
| Sending alerts and reports to the channels you configure | Notification channels, notification delivery log | Contract — Art. 6(1)(b) |
| Invoicing you and keeping the required accounting records | Account data, billing data | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) for statutory retention of accounting records |
| Keeping the platform secure: rate-limiting logins, recording administrator “view as user” sessions with IP address and user-agent, investigating abuse | Security records | Legitimate interests — Art. 6(1)(f): securing a multi-tenant system and being able to reconstruct who accessed what |
| Support: answering the messages you send us | Account data and whatever you include in the message | Contract — Art. 6(1)(b), or legitimate interests — Art. 6(1)(f) where you are not yet a customer |
| Optional communications you ask for (where we introduce any) and any future processing that is not covered above | E-mail address | Consent — Art. 6(1)(a), withdrawable at any time |
Where we rely on legitimate interests, we have weighed those interests against your rights. The security records are minimal, are visible to workspace administrators, and exist so that privileged access to your data cannot happen silently — which is in your interest as much as ours. You may object to this processing under Art. 21; see section 10.
We do not process special categories of personal data (Art. 9), and we ask you not to enter any into the platform.
6.Who we share data with
We do not sell personal data and we do not share it for advertising. Data reaches only the following recipients:
| Recipient | Purpose | Location |
|---|---|---|
| Xorek.Cloud / DpkgSoft International Limited | Server hosting: the application, the database and the database backups | Amsterdam, Netherlands (EU) |
| Cloudflare | CDN and reverse proxy; terminates TLS, so all traffic to the site passes through it | Global edge network; Cloudflare, Inc. is established in the United States |
That is our entire infrastructure today. If the operator later configures outbound e-mail (SMTP) or Telegram alerting, the provider of that service becomes an additional sub-processor, and we will list it here and in the DPA before it starts processing data. Webhook alerts send data to an endpoint you choose; where it goes after that is your responsibility.
We may also disclose data to professional advisers, or to a public authority or court where we are legally required to. If we are ever compelled to hand over customer data, we will notify you unless the law forbids it.
7.Where your data is stored, and international transfers
All application data and all database backups are stored on a single server in Amsterdam, the Netherlands, inside the EU. We use no other hosting provider and no other region.
Traffic to zutpralik.click passes through Cloudflare, which acts as our CDN and terminates TLS. Cloudflare, Inc. is a US company, so this involves a transfer of data in transit (including IP addresses and request contents) outside the EEA. That transfer relies on the European Commission’s Standard Contractual Clauses and Cloudflare’s data-processing addendum, together with the technical and organisational measures Cloudflare applies under it.
A copy of the relevant transfer safeguards is available on request at [[CONTACT_EMAIL]].
8.How long we keep data
| Data | Retention |
|---|---|
| Raw monitoring checks (the individual result of each probe) | 30 days on Basic, 180 days on Pro, 365 days on Business. Older rows are deleted by a nightly job. |
| Database backups | 14 daily and 8 weekly copies, held on the same server. Older copies are rotated out. |
| Account data | For as long as the account exists; deleted on request (see section 10). |
| Incidents, invoices, activity events, notification delivery logs and the impersonation audit log | Currently kept indefinitely. |
| Invitations | Expire 7 days after they are issued. |
| Password-reset tokens | Stored only as a hash; expire 60 minutes after they are issued and are single-use. |
9.How we protect data
The measures below are the ones actually in place today:
- Passwords are hashed with bcrypt. We never store or display a password, and we cannot recover one.
- Password-reset links are single-use, time-limited (60 minutes) and stored only as hashes, so a leaked database does not yield usable reset links.
- TLS in transit, terminated by Cloudflare, for all traffic between your browser and the platform.
- Strict tenant isolation: every database query is scoped by tenant, so one workspace cannot read another’s data.
- Rate-limited authentication, to blunt credential-stuffing and brute-force attempts.
- Administrator “view as user” sessions are recorded in an audit log with the administrator’s identity, IP address and user-agent, and the session token expires after 60 minutes.
- Daily backups, with restores verified rather than assumed.
- Server access is by SSH key only; password login is disabled.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to [[CONTACT_EMAIL]] and give us a reasonable opportunity to fix it before disclosing it.
10.Your rights
Where we are the controller, you have the following rights under the GDPR. Where we are only the processor (see section 2), address your request to the agency that holds your data; we will assist them.
- Access (Art. 15) — confirmation of whether we process your data, and a copy of it.
- Rectification (Art. 16) — correction of inaccurate or incomplete data. Most account fields you can correct yourself in the application.
- Erasure (Art. 17) — deletion of your data, unless we must keep it (for example, invoices retained under accounting law).
- Restriction (Art. 18) — a pause on processing while a dispute about accuracy or lawfulness is resolved.
- Portability (Art. 20) — the data you gave us, in a structured, commonly used, machine-readable format, or transmitted to another provider where technically feasible.
- Objection (Art. 21) — to processing based on legitimate interests, including the security and audit logging described in section 4.
- Withdrawal of consent (Art. 7(3)) — at any time, where processing is based on consent. This does not affect processing carried out before you withdrew it.
- Complaint to a supervisory authority (Art. 77) — you can lodge a complaint with the data protection authority of the EU/EEA member state where you live, work, or where you believe the infringement occurred. In the Netherlands, where our servers are located, that is the Autoriteit Persoonsgegevens. Our lead authority is the one in [[GOVERNING_LAW_COUNTRY]].
To exercise any of these, write to [[CONTACT_EMAIL]]. We answer within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. Exercising your rights is free; we may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive. We may ask you to confirm your identity before we act.
11.Data breaches
If a personal data breach occurs and it is likely to result in a risk to people’s rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (Art. 33), and we will inform affected users without undue delay where the risk is high (Art. 34). Where we act as a processor, we notify the controller without undue delay — see the DPA.
12.Children
zutpralik is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact [[CONTACT_EMAIL]] and we will delete it.
13.Changes to this policy
We update this policy when the platform changes — for example when a sub-processor is added, when origin encryption is enabled, or when retention periods are introduced for the records listed as “indefinite” in section 8. The “last updated” date at the top of this page always reflects the current version. Where a change materially affects your rights, we will notify account holders by e-mail before it takes effect.